
Varonis details Dialogflow CX flaw exposing enterprise AI security gaps
Varonis Threat Labs found a permission flaw in Google's Dialogflow CX in July 2026 that may have allowed attackers with certain access to take over chat sessions, steal data, and send phishing prompts. This issue, called Rogue Agent, mainly threatened organizations if insiders or compromised developer accounts misused their permissions. Google fixed the flaw in June 2026 and said there was no sign of customer harm. The event suggests that AI agents need strong security controls like unique identities, frequent credential changes, and careful permission checks. Experts recommend regular audits, separating human and machine credentials, and testing for unusual activity to help prevent similar security gaps.













